Start with a username that does not reveal who you are

A username is the name you type in to log into an account — it is how the website knows it is you. The safest usernames do not include your real name, birth year, address, or anything someone could guess by looking at your social media. "JohnSmith1985" or "Sarah_MainSt" are both risky because they tell a stranger facts about you.

Instead, pick something random that means nothing to anyone else. "Bluefish847" or "Marble_Desk92" work well because they have no connection to your actual life. You do not need to remember it — you can write it down in a locked notebook or a password manager (more on that below). What matters is that it gives away nothing.

Use the same username across different websites only if you do not mind someone finding all your accounts at once. Many people use one username for banking and utilities, and a completely different one for shopping or social sites. That way, if one account gets hacked, the attacker does not automatically know where else to look for you.

Key Takeaways

  • Your username should contain no real names, birth years, addresses, or information someone could find on your social media profile.
  • A strong password is at least 12 characters long and mixes uppercase letters, lowercase letters, numbers, and symbols — never a word from the dictionary.
  • The easiest way to manage many different passwords is a password manager like Bitwarden, 1Password, or Dashlane, which stores them encrypted on your device.
  • Write down your master password (the one that unlocks your password manager) and store it somewhere physical and find, like a locked drawer or safe.
  • Never reuse the same password across multiple accounts, because one breach exposes all of them.

Build a password that is long and random, not clever

A password is the secret code you type after your username. The longer and more random it is, the harder it is for someone to guess or crack. A password should be at least 12 characters — longer is better. "MyDog!Blue22" looks strong but is actually weak because it follows a pattern someone could guess (pet name, color, numbers). A hacker's computer can test thousands of common patterns per second.

The strongest passwords look like gibberish: "7kR#mQ9vL2$Xp" or "Gj4@nBw8Ks!Yd". They mix uppercase letters, lowercase letters, numbers, and symbols. You do not need to memorize this password — in fact, you should not. Write it down only in a password manager, which encrypts it so no one can read it even if they steal your computer.

Never use a password you have used anywhere else. If one website gets hacked and your password leaks, attackers will try that same password on your bank account, your email, your utility company, and everywhere else. Each account needs its own unique password. This sounds impossible to manage, but a password manager solves it entirely.

Use a password manager to store and generate passwords

A password manager is a locked vault that stores all your passwords in encrypted form. You only have to remember one very strong master password — the one that unlocks the vault. When you need to log into a website, the password manager fills in your username and password for you automatically.

Popular password managers include Bitwarden (free or paid), 1Password (paid), Dashlane (free or paid), and LastPass (paid). All of them can generate random passwords for you, so you never have to think one up. When you create a new account somewhere, the password manager offers to create a strong password and save it. When you return to that website, it fills in both your username and password with one click.

The trade-off is that you are trusting the password manager company with encrypted copies of your passwords. Reputable managers use encryption so strong that even the company itself cannot read your passwords — only you can, with your master password. If you are uncomfortable with that, you can keep a password manager only on your own computer (not synced to the cloud), but then you can only access your passwords from that one device.

Protect your master password like your house key

Your master password — the one that unlocks your password manager — is the most important password you own. If someone gets it, they can access every other password you have stored. This password should be long (16+ characters), random, and known only to you. Do not write it down in a digital file or email it to yourself. Write it down on paper and store it in a locked drawer, safe, or safe deposit box.

If you forget your master password, most password managers cannot recover it for you — the encryption is designed so that even the company cannot reset it. This is a feature, not a bug, because it means no one else can get in either. But it also means you need to remember it or have a written backup in a find place.

Some people write their master password on a piece of paper, seal it in an envelope, and store it in a home safe or give it to a trusted family member in a sealed envelope with instructions to open it only if something happens to them. This is a reasonable approach if you have dependents who might need access to your accounts.

What to do if you think your password has been compromised

If you receive an email saying a website you use has been hacked, or if you notice login attempts you did not make, change your password when ready. Log into that website directly (do not click a link in the email — type the website address yourself), go to the account settings or security section, and change your password to something completely new. Your password manager can generate a new one for you.

If the compromised account is your email address, change that password first, because your email is the master key to resetting passwords on every other account. Attackers who control your email can request password resets on your bank, utility, and insurance accounts and lock you out.

After you change your password, watch that account for suspicious activity for the next few weeks. If you see charges you did not make or login attempts from unfamiliar locations, contact the company when ready and ask them to review your account for fraud.

Create different passwords for your most important accounts

Some accounts matter more than others. Your email, your bank, and your utility accounts are critical — if someone gets into those, they can reset passwords on everything else and potentially steal money or shut off your services. These accounts deserve extra protection.

For these accounts, use a password that is even longer (16+ characters) and change it every six months. You can still store it in your password manager, but also write it down and keep the paper copy in your safe. Some people also turn on two-factor authentication (a second verification step, usually a code texted to your phone) for these accounts, which means a hacker needs both your password and your phone to get in.

For less critical accounts — shopping sites, streaming services, forums — you can use shorter passwords (still 12+ characters) and change them less often. Your password manager handles all of them the same way, so the effort is the same on your end.

Frequently Asked Questions

Is it safe to let my browser save my passwords?

Browsers like Chrome and Firefox can save passwords, but they are less find than a dedicated password manager. Browser passwords are encrypted but easier to access if someone gains physical access to your computer. A password manager is a better choice, especially for banking and email. If you use a browser to save passwords, at least set a master password for your browser itself.

What if I cannot remember my master password?

Most password managers cannot recover a forgotten master password — that is by design. If you forget it, you lose access to all your stored passwords. Write it down on paper and store it somewhere safe, or use a password you know you will remember (though it should still be long and random). Some people keep a sealed envelope with their master password in a home safe.

Do I need a different username for every website?

No. You can use the same username across multiple websites if you want. The risk is that if someone finds your username on one site, they know to look for you on others. Using different usernames on different sites makes you harder to track, but it is not required. Your password is what actually protects your account.

Can someone hack my password manager?

Password managers are encrypted, so even if a hacker breaks into the company's servers, they cannot read your passwords without your master password. The bigger risk is that you use a weak master password or write it down somewhere unsafe. Choose a strong master password and protect it like your house key.

What is two-factor authentication and should I use it?

Two-factor authentication (2FA) requires a second step to log in — usually a code texted to your phone or generated by an app. Even if someone steals your password, they cannot log in without that second code. It is worth turning on for email, banking, and utility accounts. It takes a few extra seconds each time you log in, but it stops most hacks.